Securing SDN Southbound and Data Plane Communication with IBC

被引:13
|
作者
Lam, JunHuy [1 ]
Lee, Sang-Gon [1 ]
Lee, Hoon-Jae [1 ]
Oktian, Yustus Eko [1 ]
机构
[1] Dongseo Univ, Dept Ubiquitous IT, Div Comp & Informat Engn, Busan 617716, South Korea
基金
新加坡国家研究基金会;
关键词
KEY AGREEMENT PROTOCOLS; IDENTITY;
D O I
10.1155/2016/1708970
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In software-defined network (SDN), the southbound protocol defines the communication between the control plane and the data plane. The agreed protocol, OpenFlow, suggests securing the southbound communication with Transport Layer Security (TLS). However, most current SDN projects do not implement the security segment, with only a few exceptions such asOpenDayLight, HP VANSDN, and ONOS implementing TLS in the southbound communication. From the telecommunication providers' perspective, one of the major SDN consumers besides data centers, the data plane becomes much more complicated with the addition of wireless data plane as it involves numerous wireless technologies. Therefore, the complicated resource management along with the security of such a data plane can hinder the migration to SDN. In this paper, we propose securing the distributed SDN communication with a multidomain capable Identity-Based Cryptography (IBC) protocol, particularly for the southbound and wireless data plane communication. We also analyze the TLS-secured Message Queuing Telemetry Transport (MQTT) message exchanges to find out the possible bandwidth saved with IBC.
引用
收藏
页数:12
相关论文
共 50 条
  • [31] Detecting IP Prefix Mismatches on SDN Data Plane
    Tung, Shu-Po
    Lin, Yu-Min
    Chang, Keng-Lun
    Hsiao, Hsu-Chun
    Kim, Tiffany Hyun-Jin
    2024 33RD INTERNATIONAL CONFERENCE ON COMPUTER COMMUNICATIONS AND NETWORKS, ICCCN 2024, 2024,
  • [32] Securing middlebox policy enforcement in SDN
    Bu, Kai
    Yang, Yutian
    Guo, Zixuan
    Yang, Yuanyuan
    Li, Xing
    Zhang, Shigeng
    COMPUTER NETWORKS, 2021, 193
  • [33] Multi-path Load Balancing for SDN Data Plane
    Nkosi, M. C.
    Lysko, A. A.
    Dlamini, S.
    2018 INTERNATIONAL CONFERENCE ON INTELLIGENT AND INNOVATIVE COMPUTING APPLICATIONS (ICONIC), 2018, : 229 - 234
  • [34] A tool for tracing network data plane via SDN/OpenFlow
    Wang, Yangyang
    Bi, Jun
    Zhang, Keyao
    SCIENCE CHINA-INFORMATION SCIENCES, 2017, 60 (02)
  • [35] Flowinsight: decoupling visibility from operability in SDN data plane
    Li, Yuliang
    Yao, Guang
    Bi, Jun
    SIGCOMM'14: PROCEEDINGS OF THE 2014 ACM CONFERENCE ON SPECIAL INTEREST GROUP ON DATA COMMUNICATION, 2014, : 137 - 138
  • [36] FlowInsight: Decoupling Visibility from Operability in SDN Data Plane
    Li, Yuliang
    Yao, Guang
    Bi, Jun
    ACM SIGCOMM COMPUTER COMMUNICATION REVIEW, 2014, 44 (04) : 137 - 138
  • [37] StateFit: A security framework for SDN programmable data plane model
    Hwang, Ren-Hung
    Van-Linh Nguyen
    Lin, Po-Ching
    2018 15TH INTERNATIONAL SYMPOSIUM ON PERVASIVE SYSTEMS, ALGORITHMS AND NETWORKS (I-SPAN 2018), 2018, : 160 - 165
  • [38] Stochastic Pre-Classification for SDN Data Plane Matching
    McHale, Luke
    Casey, Jasson
    Gratz, Paul V.
    Sprintson, Alex
    2014 IEEE 22ND INTERNATIONAL CONFERENCE ON NETWORK PROTOCOLS (ICNP), 2014, : 596 - 602
  • [39] FORTRESS: An Efficient and Distributed Firewall for Stateful Data Plane SDN
    Caprolu, Maurantonio
    Raponi, Simone
    Di Pietro, Roberto
    SECURITY AND COMMUNICATION NETWORKS, 2019, 2019
  • [40] DDoS Attack Detection and Mitigation at SDN Data Plane Layer
    Abdulkarem, Huda Saleh
    Dawod, Ammar
    2020 IEEE 2ND GLOBAL POWER, ENERGY AND COMMUNICATION CONFERENCE (IEEE GPECOM2020), 2020, : 322 - 326